cbcvebase.
CVE-2016-3084
published 2022-05-13

CVE-2016-3084: CVE-2016-3084 [HIGH] Cloud Foundry UAA reset password vulnerable to brute force attack Cloud Foundry UAA reset password vulnerable to brute force attack The…

PriorityP344high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.19%
64.1th percentile
CVE-2016-3084 [HIGH] Cloud Foundry UAA reset password vulnerable to brute force attack Cloud Foundry UAA reset password vulnerable to brute force attack The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.